8

CVSS3.1

CVE-2026-25037 - Copeland XWEB and XWEB Pro OS Command Injection

An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attacker to achieve remote code execution on the system by configuring a maliciously crafted LCD state which is later processed during system setup, enabling remote code execution.

πŸ“… Published: Feb. 27, 2026, 12:59 a.m. πŸ”„ Last Modified: April 16, 2026, 3:45 p.m.

8

CVSS3.1

CVE-2026-25196 - Copeland XWEB and XWEB Pro OS Command Injection

An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attacker to achieve remote code execution on the system by injecting malicious input into the Wi-Fi SSID and/or password fields can lead to remote code execution when the configuration i…

πŸ“… Published: Feb. 27, 2026, 12:58 a.m. πŸ”„ Last Modified: April 16, 2026, 3:45 p.m.

8

CVSS3.1

CVE-2026-20764 - Copeland XWEB and XWEB Pro OS Command Injection

An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attacker to achieve remote code execution on the system by providing malicious input via the device hostname configuration which is later processed during system setup, resulting in remo…

πŸ“… Published: Feb. 27, 2026, 12:56 a.m. πŸ”„ Last Modified: April 16, 2026, 3:45 p.m.

8

CVSS3.1

CVE-2026-25721 - Copeland XWEB and XWEB Pro OS Command Injection

An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attacker to achieve remote code execution on the system by injecting malicious input into the server username and/or password fields of the restore action in the API V1 route.

πŸ“… Published: Feb. 27, 2026, 12:55 a.m. πŸ”„ Last Modified: April 16, 2026, 3:45 p.m.

8

CVSS3.1

CVE-2026-23702 - Copeland XWEB and XWEB Pro OS Command Injection

An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attacker to achieve remote code execution on the system by sending malicious input injected into the server username field of the import preconfiguration action in the API V1 route.

πŸ“… Published: Feb. 27, 2026, 12:54 a.m. πŸ”„ Last Modified: April 17, 2026, 2:15 p.m.

8

CVSS3.1

CVE-2026-24452 - Copeland XWEB and XWEB Pro OS Command Injection

An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attacker to achieve remote code execution on the system by supplying a crafted template file to the devices route.

πŸ“… Published: Feb. 27, 2026, 12:53 a.m. πŸ”„ Last Modified: April 17, 2026, 2:15 p.m.

8

CVSS3.1

CVE-2026-25105 - Copeland XWEB and XWEB Pro OS Command Injection

An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attacker to achieve remote code execution on the system by injecting malicious input into parameters of the Modbus command tool in the debug route.

πŸ“… Published: Feb. 27, 2026, 12:52 a.m. πŸ”„ Last Modified: April 16, 2026, 3:45 p.m.

8

CVSS3.1

CVE-2026-24695 - Copeland XWEB and XWEB Pro OS Command Injection

An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attacker to achieve remote code execution on the system by injecting malicious input into OpenSSL argument fields within requests sent to the utility route, leading to remote code ex…

πŸ“… Published: Feb. 27, 2026, 12:51 a.m. πŸ”„ Last Modified: April 16, 2026, 3:45 p.m.

8

CVSS3.1

CVE-2026-20902 - Copeland XWEB and XWEB Pro OS Command Injection

An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attacker to achieve remote code execution on the system by injecting malicious input into the map filename field during the map upload action of the parameters route.

πŸ“… Published: Feb. 27, 2026, 12:49 a.m. πŸ”„ Last Modified: April 18, 2026, 10:30 a.m.

8

CVSS3.1

CVE-2026-25109 - Copeland XWEB and XWEB Pro OS Command Injection

An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attacker to achieve remote code execution on the system by injecting malicious input into the devices field when accessing the get setup route, leading to remote code execution.

πŸ“… Published: Feb. 27, 2026, 12:48 a.m. πŸ”„ Last Modified: April 16, 2026, 3:45 p.m.
Total resulsts: 349182
Page 1411 of 34,919
Β« previous page Β» next page
Filters